Weyvox documentation
Weyvox is the phone line of a small business with an AI on it — an app for iPhone and Android. The iPhone app is available now on the App Store; the Android app is in development, with release planned for 1 October 2026. Where this document names platform frameworks, it describes the iOS implementation. The line is a number plus an agent plus the back office, in one place: the agent answers your customers in your business name, takes the order, calls out on your behalf, texts a confirmation and writes the invoice afterwards — and the number is either one you buy inside the app or your own business number connected by forwarding. The app and the agent are not sold by the month: you pay for minutes, calls and what the agent actually does, from a prepaid balance. Two subscriptions exist and the user chooses both — a Weyvox phone number and each extra team member. It is written for sole traders and small businesses where the owner is also the person who answers the phone; the trade is picked from 16 ready-made business types the first time the app opens, and it decides what the agent knows and how orders are named. A business that has staff adds executors — people who sign in with an access code, without registering, and work the orders assigned to them. This document is the definitive reference: what the product does, and how it works — which parts are built on the platform's system frameworks and which parts are Weyvox's own engineering. For a screen-by-screen map of the app — every page, every setting and what it controls — see the Weyvox app map.
Product overview
Weyvox is the phone line of your business with an AI on it: it answers your customers, takes the order and writes the invoice. A line here is three things in one app — a phone number, an agent that works it, and the back office behind it. The number is either one you buy inside the app or the business number you already have, connected by forwarding. The app and the agent are not sold by the month: you pay for minutes, calls and what the agent actually does, from a prepaid balance. Two subscriptions exist and the user chooses both — a Weyvox phone number and each extra team member (€10 a month). Data is held in the EU.
It is written for sole traders and small businesses — one to ten people, no receptionist, the kind of business where the owner is also the person who answers the phone. The phone rings while your hands are busy, the call goes unanswered, and most people who cannot get through simply call the next name. What changes is that the line answers even when you cannot: the agent takes the order at your prices, agrees a time from your genuinely free windows, confirms it by SMS and writes the invoice. Afterwards there is a customer, an order, a document and a reminder — and every Monday, the week in numbers.
The business owner — the administrator — has four tabs: Line (your number, the state of the line, and every conversation on it: the Weyvox system chat, a thread per customer number, personal chats), Weyvox (the AI agent and its tools), Business (business management: business information, customers, orders, documents, analytics, team, PDF templates), and Settings (profile, phone numbers, balance, tariffs, data, agent configuration). There is no Contacts tab and no separate dialer: the dial pad lives in Settings → Keyboard, and every call is recorded as a call bubble in the thread of that number. An executor — a team member signed in with an access code — gets a reduced app of four other tabs, described under Team.
- Free: personal chats (text, photos, video, files, voice, location) between people by phone number, cloning your own voice for the agent, the first 5 GB of media storage, and the €5 welcome credit.
- Paid, from a prepaid in-app balance: calls over the telephone network, the AI agent, AI call notes, SMS to customers, storage above 5 GB, phone numbers and executors on the team. Full prices: weyvox.com/pricing.
First run — "Line ready N of 4"
Registration is a phone number and a one-time SMS code, first and last name, and one card with two checkboxes — "I am 18 or older" and consent to the Terms. Date of birth is optional; being 18 or over is a condition, and the server refuses an account without that confirmation. There is no email. Under "Sign in" there is a second door — "I have an executor code" — for staff who never register at all.
A new administrator then walks a four-step wizard. Every step can be skipped with "Later"; the state is derived from the data rather than stored as a checklist, so the wizard resumes at the first unfinished step and the Line tab keeps a card "Line ready N of 4 · Continue" until it is done.
- What you do — one of 16 business types (or "Other"), plus the business name.
- Agent voice — a ready-made voice, or a clone of your own.
- Auto-answer — whether the agent picks up when you do not, and after how long.
- Your line — buy a Weyvox number, connect the number you already have, or carry on without a number for now.
Business types — 16 ready-made profiles
The trade is not a label in a profile: it is what the agent knows before it has been told anything. One of the sixteen is picked during first run, and it can be changed later in Business → Business information → Business type. If none of them fits, Other lets the agent run a short interview in the chat and fill the profile itself.
- Transport — takes the pickup: where from, where to, when, passengers or flight. Stages: accepted → picked up → delivered.
- Restaurant, café — books a table or takes a delivery order from your menu, confirms the time by SMS.
- Shop — takes orders for your goods, promises a ready-by time, keeps the customer card.
- Hair salon, barber — books appointments only into free windows; stages: booked → arrived → done.
- Nails, beautician — books the treatment, remembers the regular, sends the reminder.
- Vet clinic — records the pet: name, species, age; and books the visit.
- Doctor, dentist — books the patient, asks what the complaint is, notes the insurance.
- Car service — takes the car in: model, plate, mileage; tells the customer when it is ready.
- Construction, repair — takes the job: type of work, area, address; agrees a start date.
- Device repair — notes the device and the fault, quotes from your price list, sets a ready-by time.
- Cleaning — takes the address and the area, books a time, sends the confirmation.
- Concierge — takes the request: when, where, how many guests; and keeps it on the order.
- Hotel, rentals — books the stay: check-in, check-out, guests, room type.
- Courses, tutoring — enrols the student, notes the level and the course, books the lesson.
- Real estate — books the viewing, records the budget and whether it is a sale or a rental.
- Travel, tours — takes the enquiry: destination, dates, travellers; holds the booking and confirms it.
What choosing a type actually changes:
- A profile skeleton — a starting description, a price-list skeleton, a business FAQ, and a first cut of what the agent may promise on its own versus what it leaves to the owner.
- The words of the order — the three working stages and the names of the standard fields are re-labelled in the language of the trade: "Accepted → Picked up → Delivered" in transport, "Booked → Arrived → Done" in a salon; "Pickup time", "Check-in" or "Appointment time" instead of a generic "Start"; "Where to" or "Site address" instead of a generic address.
- 0–3 custom order fields that only that trade needs — car, plate and mileage in a garage; pet name, species and age in a vet clinic; from, passengers and flight number in transport.
It is renaming and pre-filling, not a separate product per trade: there is one order screen and one pipeline underneath, and no trade gets a screen of its own — no separate timetable page, no list of trips.
Calls & telephony
Weyvox is a telephone product, and there is only one kind of call: a call over the public telephone network, made from and received on a real number — the Weyvox operator number you bought in the app, or your own business number forwarded into it. There are no app-to-app calls between Weyvox accounts, no internet calling and no separate free tier of calling: a number is what a line is made of. Every call is billed at the per-minute rate for the destination country (see pricing), and an agent call adds the agent's own per-minute work on top.
Calls over the telephone network (PSTN)
With a real phone number, users call any phone worldwide and receive calls from any phone. Outbound and inbound legs run through a carrier-grade telephony backbone; Weyvox's own orchestration layer controls each call (dial, answer, bridging, hangup) through the carrier’s verified call-control interface. Costs are computed from the carrier's own post-call cost events — the exact cost of each call, not an estimate (see Billing). Incoming calls ring through the phone's native call screen, including from the lock screen.
Real phone numbers
- One operator number per account. Numbers are provisioned per country in E.164 format; the number carries a monthly service fee that depends on the country and the number itself — it is shown on the purchase screen before you pay, and the first month is included in the purchase.
- Identity checks where the regulator asks for them. Where regulators require identity verification (KYC), the app collects exactly the documents the carrier lists, submits them, and auto-deletes them within 24 hours of activation (see Privacy Policy).
- Immediate temporary number. When the chosen number needs documents, carrier activation is not instant, so paying provisions a working temporary operator number the same moment — the user can call and receive calls while the main number is under review. That stand-in is usually a number in a different country from the one ordered; it exists to keep the line working, not to preview the future number. Numbers that need no documents are activated directly, with no temporary one.
- Tracked activation with resubmission. The order is reviewed by the carrier; its status streams to an order-tracking page in the app. The carrier never rejects a purchase permanently — it can only ask for corrections, flagging the specific document while the accepted parts stay locked. The user re-uploads only the flagged documents and resubmits under the same order; each resubmission is recorded.
- Automatic switch-over on approval. When the main number is approved it activates automatically and the temporary number is disconnected and removed in the same operation — the account is never left without a number and never billed for two at once. A confirmation (number, activation time, subscription details) is posted to the system chat. Numbers you no longer hold are released with the carrier automatically, so a stalled provisioning cannot leak a paid number.
- 25-day temporary lifetime. If the main number is not approved within 25 days, the temporary number is deactivated and the user is notified; the order stays open and the main number still activates automatically once approved.
- Subscription & cancellation. A monthly subscription engine charges the number's service fee from the balance (the first month is included in the purchase), if the balance is short the number keeps working for 30 days while the charge is retried daily, then outgoing calls from it are blocked for another 30 days, and on day 60 the number is released. Only the user can cancel a purchase; a cancellation releases the numbers and stops the subscription, and the fee already paid is not refunded (balance top-ups follow App Store rules).
Your own business number
A business that already has a number — on its cards, its storefront, its Google listing — does not have to replace it. Weyvox connects that number instead of issuing one: nothing is bought and nothing is ported. This is also the recommended setup, rather than making a Weyvox number the only work line: the business number stays with its carrier and on the cards, Weyvox answers its calls through forwarding, and switching forwarding off at the carrier returns the line to exactly how it worked before Weyvox — nothing is put at stake.
- Incoming = forwarding. The user switches call forwarding on with their own carrier, from the business number to their active Weyvox operator number (main or temporary). Forwarded calls arrive with the original caller's number, and Weyvox can tell they came in on the business line — so the agent answers knowing which line it is on and greets the caller with the business name. Forwarding lives in the user's carrier network: Weyvox can neither switch it on nor read its state, so the app presents it as a method with setup instructions, never as a status it verifies.
- Outgoing = verified caller ID. Ownership is proven with a one-time code (SMS to a mobile line, a voice call to a fixed one), after which outgoing calls can present the business number instead of the Weyvox number. This is a per-account toggle and it applies only to a verified number; if the recipient's network withholds a substituted caller ID, the app warns and the call can fall back to the Weyvox number.
- One-time €5 connection fee. Charged from the balance at the moment the confirmation code is requested — before any code is ordered, so verification can never be triggered for free. Resending the code to the same number is free, and a failed connection is refunded automatically. There is no monthly fee for the connection itself; forwarded minutes are billed by the user's own carrier at the user's own rates. Disconnecting and reconnecting later is charged again.
- Tied to an active Weyvox number. A business number can only be connected while an operator number (main or temporary) is active, and the connection is removed automatically in every path where that receiving number disappears — swap, expiry, cancellation, replacement, deletion for non-payment — with a system-chat notice, because forwarding would otherwise point at a line that no longer exists.
SMS to customers
A phone call ends and the customer forgets the time. Weyvox closes that gap with a short text message sent from your own line — never a marketing channel, only the confirmation of something that was just agreed.
- Confirmation of an agreement made on a call. When a call produces something concrete — a booking, a pickup time, an address, a price — the agent offers to text it, and sends the message only after the customer says yes. The text opens with your business name, carries facts only, and is written in the customer's language.
- Missed call → text back. A toggle on the auto-answer page ("Missed call → SMS to customer"). When neither you nor the agent picked up, the caller gets a short message from your number saying you will call back — the customer who would otherwise dial your competitor gets an answer within seconds.
- On request, from the chat. "Text Anna that the car is ready" — the agent writes it and sends it to the number on that customer's card.
- Sent from your Weyvox operator number. SMS exists only while you hold an operator number; a connected business number cannot send them, because the forwarding path carries voice only.
- Priced per segment — about €0.15. A segment is 160 Latin or 70 Cyrillic characters; a message may run to three segments. The exact price is on the pricing page and in Settings → Account → Tariffs.
- Visible where the conversation is. Every message sent appears as an "SMS to customer: «…»" card in that number's thread on the Line tab, with its delivery status.
- Opt-out is honoured, and it is a web page, not a keyword. Anyone can bar Weyvox from calling or texting them at weyvox.com/optout; after that the agent neither writes nor dials that number. There is no STOP reply to a Weyvox SMS — the opt-out page is the route.
The AI agent
The agent is Weyvox's core: an AI that actually works the phone for the business it belongs to. One agent per account — it shares a single brain, memory and toolset across every surface it appears on (voice calls, the agent chat, in-chat assists, background tasks). An executor talks to the same agent, narrowed to the orders assigned to them.
What the agent can do
- Call real numbers on the user's behalf — book a table, ask a business a question, negotiate a price, chase a delivery. Before dialing it shows a confirmation card (users can switch to instant calling); after the call it returns the outcome and a short note into the chat.
- Answer incoming calls — it can pick up for the user, including auto-answering every incoming call after a chosen delay.
- Take over a live call — during any call, the user hands the agent the "seat": it speaks to the other party in their place while they listen, and can be given silent instructions mid-sentence. See the seat model.
- Text a customer — a confirmation of what was just agreed on a call, an automatic reply to a missed call, or a message you dictate in the chat. See SMS to customers.
- Navigate phone menus — it recognises IVR menus and presses the right keys (DTMF) to reach a human or the right department; it detects voicemail and dead-ends and finishes gracefully.
- Research on the internet — web search plus full-page reading, so it answers from live sources, not memory alone.
- Find places — "a pharmacy near me", powered by Apple's mapping services and the user's (optional) location. While the location switch is on (it is on by default) and the phone's location permission is granted, approximate coordinates travel with the user's agent-chat messages; they are used per request, not stored on the servers, and never used on the agent's phone calls.
- Run Business management — the owner's business profile, price list, customers, orders and documents: it reads all of it, quotes prices only from the list, checks the free slots before naming a time, logs developments into existing orders, and records agreed dates with reminders, so "book it and write it down" is one instruction. See Business management.
- Use the address book — when a call needs a number the owner has only as a name ("call the supplier"), it resolves it through the phone's own contact names. This is the agent's own contacts switch. While it is on, a snapshot of your address book — names and phone numbers only — is kept on the server so the agent can find a number to call; switch it off and that copy is deleted. Nothing else in Weyvox reads your contacts.
- Read the user's chats — governed by its own switch, on by default and switchable off at any time: while it is on, the agent can be opened inside a conversation and look up what was agreed there ("what address did Anna send me?"), including voice messages, photos and files. See Weyvox inside a personal chat.
- Track phone-number orders — it can report the live status of a number purchase, including which document needs fixing.
- Understand media — photos and files sent in chat are analysed once (text, numbers, links extracted) and their content stays available for the rest of the conversation.
- Run multi-step background tasks — see below.
Every capability is governed by a per-user switch — telephony, business management, contacts (the agent may look up a number in the phone's address book in order to dial it), location and personal chats. All five are on by default and can be switched off at any time; the one capability deliberately withheld until the user enables it is calls placed during background tasks. Each switch takes effect immediately across all surfaces.
The agent inside a live call — the seat model
This is the part of Weyvox with no obvious equivalent elsewhere, and it works the same way on every call the line carries — one the agent placed, one it auto-answered, one the owner picked up by hand.
The rule is simple: each side of a call has exactly one voice. On the user's side that voice is either the user or their agent — never both. Two people plus two agents all talking into one line is chaos, so Weyvox does not do it. Handing the agent the "seat" is a single button on the call screen.
Handing over, and taking it back
- Bringing the agent in — one tap during any live call. The agent takes the seat by default: it starts speaking to the other party as the user, not as a third participant that joined. The other party hears only the agent.
- The user stays on the line — they hear everything, in real time, for the whole call. They are simply not the voice at that moment.
- "Take the conversation back" — the same button, reversed. The user's microphone returns to the line and the agent goes silent instantly. It keeps listening and keeps taking notes; it just stops speaking.
- Handing it back — the agent resumes mid-conversation, already knowing everything that was said while it was silent. It does not re-introduce itself and does not start over.
- The agent never hangs up. The call belongs to the user; only the user ends it. When the agent has achieved what the call was for, it states the outcome out loud and stops talking.
Whispering to the agent while it is speaking
The user can talk to their own agent, during the call, while the agent is mid-sentence — and the other party hears none of it. This is the capability people ask about most, so it is worth being precise about what it does:
- It does not interrupt. The agent finishes its current sentence rather than cutting itself off. The instruction is folded into what it says next — which is what makes it usable in a real conversation instead of a source of stutter.
- It is an instruction, not a dialogue. "Ask about the price", "agree to Tuesday", "switch to English" — the agent carries it out in what it says to the other party. It never answers the user out loud, because every word it speaks is heard by the other side.
- Silence is a valid response. If a whisper needs nothing new said right now, the agent says nothing at all and simply acts on it. It does not narrate that it heard you.
- How it is possible. The device captures the microphone twice: once for the call itself (muted toward the other party while the agent holds the seat) and once on a separate private path to the agent. On the operator side this second path is what makes whispering work at all — a phone network alone cannot separate "silent to the caller" from "audible to my assistant".
What the mute button means here
Because the seat already keeps the user silent toward the other party, the mute button means something more specific during an agent call: "my agent should not hear me either". Turning it on closes the private channel; the agent is told, and carries on with the conversation alone. It is off by default, so the user can steer from the first second.
The agent knows which way the call went
Inbound and outbound calls are opened in opposite ways, and the agent is told which one it is. On a call the user placed, the business is theirs to raise and the agent states it immediately. On a call someone made to the user, the business belongs to the caller — the agent invites them to say why they are calling instead of announcing an agenda of its own.
What the agent does mid-call, without being asked
- Checks the free windows before it names an hour. Before offering a customer a time — an appointment, a visit, a pickup, a delivery — it takes the business's working hours, subtracts the orders already scheduled, and offers only what is genuinely free. It never invents a slot and never double-books. It quotes prices only from the price list, and records the appointment on the matching order once a time is settled — setting the order's dates (with a reminder when wanted) and logging what was agreed — so "book it" is finished, not promised. It may only touch the order this call is about; the owner's other orders are never changed, and it never marks anything paid.
- Looks things up on the web silently when the answer decides what to say next — an address, opening hours, a price — and answers from what it found.
- Keeps the user's memory current as durable facts come up, so the next call already knows them.
It does none of this out loud: no "let me check the schedule", just the outcome — "Tuesday at 18:00 is free, booking it now".
After the call
- An attributed transcript. Weyvox records who said what and when — the user, the other party, and the agent are separate speakers, because each reaches the system on its own stream rather than being guessed apart afterwards. Whispers are marked as a distinct kind of line: they were instructions to the agent, not things the other party heard, and a summary that confused the two would record agreements that never happened.
- A note, written to the user's own instructions. The note follows the same configured style and language as every other Weyvox call note, and lands on the call in the chat with that person.
- Commitments reported separately. If something was actually agreed — a meeting, a call-back, a deadline, an amount — it is posted as its own message in the Weyvox system chat — because after hanging up nobody goes looking inside a note to find out what they now owe. Only firm agreements are reported; if the call was just a conversation, nothing is posted.
- Turning the agent off mid-call erases everything it collected — the transcript is discarded, no note is written, and nothing further is recorded. The same rule as switching off an ordinary call note.
The agent always identifies itself as an AI assistant acting for its user at the start of a call — in Weyvox this is a product rule, not a setting, and it matches disclosure requirements for AI voice systems in the jurisdictions Weyvox serves.
Answering incoming calls — auto-answer
The agent can pick up the user's incoming calls automatically. It is switched on from the agent's settings, where the user also chooses how long the phone rings before the agent steps in — 10, 20, 30 or 40 seconds (30 by default). While it is on, it applies to every incoming call.
- The user always gets first refusal. The phone rings normally for the chosen delay. If the user answers, it is their call as usual — the agent never pre-empts them. Only if the delay elapses unanswered does the agent take the call.
- Dismissing the ring hands it over at once. Declining the incoming call is read as "you take it": the agent answers immediately instead of waiting out the rest of the timer.
- Answered on the server, not on the phone. The agent picks up from Weyvox's backend, so it works even when the user's phone is locked, asleep, out of battery or offline — which is the whole point of having it. For an operator number the routing is arranged in the network only while auto-answer is on; switching it off restores the plain inbound path unchanged.
- It behaves like the agent on any call. It introduces itself as the user's AI assistant, finds out who is calling and why, helps or takes a message, and can act mid-call (check the owner's orders, agree to a time and record it on the order). It is told this is an inbound call and opens accordingly — inviting the caller to say why they are calling rather than raising an agenda of its own.
- The full seat model applies. When the user opens the app, an auto-answered call is a live mini-card: they can listen in, whisper to the agent, or take the conversation over — exactly as on any other call.
- Afterwards a note lands on the call in that number's thread and any firm commitment is posted in the Weyvox system chat — the same as a call the agent placed. If the agent never picks up, it is recorded as an ordinary missed call.
- Nobody answered? The caller still hears back. On the same page there is a "Missed call → SMS to customer" switch: when neither the owner nor the agent took the call, a short text goes out from the line straight away. See SMS to customers.
When the balance runs out
The agent is a paid feature, so it stands down while the balance is negative (in debt) — but it never leaves a call in a broken state. The behaviour is deliberate:
- Auto-answer stands aside. The agent does not answer. The incoming call rings as a completely ordinary call — the user can still pick it up by hand — and, unanswered, ends as an ordinary missed call. It does not flash on and off or reject the caller.
- A message explains why. At the moment the agent would have answered, Weyvox posts a message in the system chat: the agent could not answer an incoming call because the balance is negative — top up to restore it. It is sent once per call, never once per ring.
- Declining ends the call. If the user dismisses the incoming call while in debt, it simply ends — cleanly, on both the caller's and the user's side — because the agent cannot step in for them.
- Joining a live call is refused visibly. Trying to hand the agent the seat during a call while in debt shows a top-up prompt on the call screen; the agent does not join and the human call carries on unaffected.
- Recovery is automatic. The instant the balance is back to zero or above, everything works again — there is nothing to re-enable.
Realtime voice pipeline & latency
- A streaming pipeline — speech recognition → reasoning model → speech synthesis — runs on every live call, with tuned voice-activity detection and natural interruption handling: when the other person starts speaking, the agent stops and listens.
- Turn-taking latency. There is a real gap between the other party finishing a sentence and the agent beginning to speak, and it is dominated by the model's thinking time — which is why calls are pinned to the fastest model rather than left to choice; the network and how much the agent has to say move it as well. Weyvox does not publish a millisecond figure, because it varies by call, by country and by what was asked.
- The brain on calls is fixed: Claude Haiku 4.5. Telephony always runs on it, and there is no setting to change that — on a live call the pause before the agent speaks is felt more sharply than depth of thought, so the lowest-latency model wins. Model choice lives in the agent chat instead, where Claude Fable 5, Claude Opus 5, Claude Sonnet 5 and Claude Haiku 4.5 are all available per thread; a more capable brain answers better and costs more per use.
- Voice — ready-made or your own. Choose the voice the agent speaks with: ready-made male and female voices (each with an audio preview in the chosen language), or clone your own voice — record a short sample and the agent speaks in a voice modelled on yours. A cloned voice is yours alone, used only for your agent, and can be deleted at any time in settings. Even when the agent uses your cloned voice, it still discloses that it is an AI at the start of every call (see AI transparency), so the other party is never misled about speaking to a machine.
- First words at pickup. The opening line is prepared while the phone is still ringing, so the conversation starts naturally the instant the call connects rather than beginning with a silence — on an auto-answered call to your line and on a call the agent places alike.
- The agent always introduces itself as an AI assistant acting for its user, and speaks the language of the call — 32 languages are supported, chosen per user and separate from the app's interface language.
Memory — how the agent remembers
The agent's memory is a layered, per-user system rather than a single transcript:
- Long-term memory — durable facts the agent saves as it works ("prefers morning appointments", "building door code", "dentist's name"), organised by category. On every turn, the agent retrieves the memories relevant to the current request and injects them into its reasoning — so it uses what matters now instead of re-reading everything it ever learned.
- Live identity profile — the user's name, age, gender and phone numbers are read fresh from the account on every session, never copied into memory; the agent always addresses and represents the user correctly, and profile changes apply instantly.
- Working context — within a conversation the agent keeps the full thread; long histories are automatically compressed into dense notes that preserve every fact, decision and number, so continuity survives without unbounded cost.
- Task journals — each background task keeps its own journal of findings and decisions (compacted as it grows); when a task finishes, the agent extracts anything durably useful into long-term memory.
- Call follow-up context — after the agent phones somewhere for the user, the call transcript stays available to the chat for 24 hours ("what exactly did they say about Thursday?"), then deletes itself.
- User control — the memory page in the app lists what the agent knows; individual entries can be managed and everything can be wiped with one action. Deleting the account deletes the memory.
Chat agent
In the Weyvox tab the agent works over text with its full tool loop. Replies stream token-by-token with a smoothing renderer; a Stop button keeps the partial answer as the reply; threads are titled automatically; a delegated task appears as a card in the chat with live status. Each one-to-one conversation can also summon a scoped in-chat assistant that sees only that conversation — see Weyvox inside a personal chat.
Weyvox inside a personal chat
Every one-to-one conversation can summon its own scoped assistant: a ✦ button in the chat header opens a mini-chat over the conversation, where the user asks Weyvox about that conversation — "summarise what we agreed", "what address did she send?", "when did he promise to call back?". It is available only while the chat access switch is on, and it keeps the agent's full abilities (calls, tasks, business management, memory) for anything the user explicitly asks.
What the in-chat assistant sees — a window on that one conversation, sent by the app. The assistant is not given a search key to your chats: the screen you opened it from assembles a recent window of that single conversation and sends it with the request, each kind of content in its own way:
- Text messages and shared locations — directly, as a transcript of the recent conversation.
- Calls — with their duration and the user's own AI call note inlined. The other person's private notes are never visible.
- Voice messages — transcribed on demand: when the user's question concerns what was said in a voice note, it is transcribed so the assistant answers from the words.
- Photos and files — referenced by number in the transcript; their content (verbatim text on a photo, the text of a PDF) is attached only when the user explicitly asks about it. Reviewing or summarising history never silently opens attachments — that keeps answers fast and avoids burning tokens on media nobody asked about.
Read once, remembered on the device. The first read of a voice message, photo or file costs a transcription or vision pass; the result is kept with the conversation on the phone, so every later question about the same attachment is answered from it at no extra cost.
Scope and privacy. The assistant is scoped to the one conversation it was opened in: it receives what that conversation's screen sent and nothing else, and no route exists from one conversation's assistant into another conversation. What it learns is used for the answer only — it does not copy the other person's messages into the agent's long-term memory unless the user explicitly asks it to remember something. It never writes into the conversation for you: whatever appears in the chat, you sent.
Billing. In-chat assistant turns are metered like any agent chat turn (tokens, plus transcription seconds when a voice message is read) and appear on the Balance & usage page as their own line — "Weyvox in a personal chat" — separate from the main agent chat.
Agent tasks (autonomous background work)
Multi-step assignments run in a dedicated task runner: the agent plans, executes tool steps, keeps a compacted work journal, verifies its own steps against the goal, asks the user when a real decision is needed (and waits), survives process restarts by re-seeding from its journal and billing state, streams live progress to the app, and can be stopped at any moment — anything already done is kept and summarised. Each task is billed as a single growing entry.
Documents the agent writes (PDF)
Asked in the chat for an invoice, a statement of completed work, a certificate, a formal letter or a written report, the agent produces a real PDF. It appears in the conversation as a file card; tapping it opens the document, and from there the user forwards, prints or saves it to Files. Beyond the five ready-made kinds it composes any other document on request — a contract, an offer, a receipt, a packing list — right in the chat. Asked for several at once, it returns several files. To change something the user does not edit the file — they say what to change in the chat and the agent rebuilds it.
- Built on the phone, filed in your archive. The agent returns the document's content and the app lays it out into the PDF; the finished file is then filed in Business → Documents — encrypted with Weyvox's own key — so it is there on any phone you sign in on. Creating documents costs nothing beyond the agent turn that composed them.
- It never invents the user's real-world data. Company name, address, tax number, bank details, amounts, dates, the recipient — anything it was not told and cannot read from the conversation it asks for first. A plausible but invented invoice is worse than no invoice, because the user may send it to a client.
- Each type is laid out as that type. An invoice carries VAT numbers, bank details and a payment deadline; a statement of work has two signature columns, because both sides sign it; a certificate drops the banking block entirely and can be issued "to whom it may concern" with no recipient at all; a letter has no heading at all — city, date, address block and a subject line, the way a business letter is actually written.
Files that are not PDFs. Arithmetic on the user’s own numbers the agent works out in code rather than in its head, and it can hand the result back as a file: a chart, an Excel spreadsheet, a Word document or a presentation. It runs in the chat, on every chat brain except the fastest one, and the finished file arrives in the conversation as a file card exactly as a PDF does.
PDF templates. Business > PDF templates — the last row of the Business tab — holds one template per document type — invoice, act, certificate, report, letter. A template carries only what is stable and the user's own: who issues it (name, tax number, address, email, phone), the banking block where the type needs one, the numbering series, a note printed on every document of that kind, who signs it, plus a logo, a signature drawn with a finger and a stamp. Everything that changes from document to document — the client, the items, the amounts, the dates, the wording — the agent fills in from the request, which is the whole point of having an agent.
- The fields differ by type, on purpose. An invoice has a VAT number and payment terms; a certificate has neither bank details nor terms but has a place of issue; a report is the shortest of all.
- The signature is drawn, not uploaded. The user signs with a finger on a white sheet in the app; the stroke is kept as a vector, so it prints smoothly at any size, and it lands on every document of that type by itself. A stamp is uploaded separately and must be a PNG or SVG — it sits over the signature, so it needs a transparent background.
- Numbers are counted by the app. The template keeps the series and the last number issued; the next one is assigned when the document is printed, and the agent is not allowed to invent it. An unbroken sequence is a legal requirement in France and Ukraine.
- Anything can be printed as a blank. The PDF button on a template prints an empty specimen of that document, so the user sees which fields exist and where they land before the first real one is made.
- Own templates. The + in the header creates a template of the user's own — they name it, describe when it applies, and add whatever fields they need in any section. Asking the agent for that document by name builds it from that template. Own templates keep the language they were written in, and the agent can fill and extend them on request — but only the user creates them, so a typo can never spawn a duplicate.
- The templates are independent of each other. Fields sharing a name are not linked, and nothing is copied between them: a person may bill from a sole proprietorship and issue certificates from a company. Filling one leaves the rest exactly as they were, and an empty field stays visibly empty rather than being quietly filled from elsewhere.
- A template holds the user's own data, never a counterparty's. When a document is made for someone else, that party goes into the document's recipient block and the templates are untouched — so a client's name can never end up heading the next invoice.
- The agent maintains them. It reads the templates on every turn and can fill or correct them itself: told something that belongs in a template ("my IBAN is…", "sign my acts as Director"), it saves it into that type's template right away and says so, instead of sending the user to a settings page to retype what they just said. It never writes a value it was not given, and it edits one template per instruction.
Task reports as PDF. The same engine exports any agent task: the task's ••• menu offers Create PDF, either with every work stage — each stage's status, summary and work journal, including what the agent achieved on calls — or with the final report only. A task still running exports whatever is already done, without asking. The document opens in the app rather than jumping straight to a share sheet.
Offline. Templates, tasks and their journals are mirrored on the device, and the PDF is drawn on the phone — so a document can be produced with no connection at all. Edits made offline are queued and reach the server by themselves once there is a network.
Business management — the whole business from the phone
The Business tab is where a small-business owner keeps everything the agent needs in order to speak for them. Seven rows, top to bottom: Business information, Customers, Customer orders, Documents, Analytics, Team, and PDF templates as the last row.
- Business information — the agent's system prompt in the shape of a form. Business name and legal name, the business type (one of the 16, or Other — changing it re-labels order stages and fields across the app; see business types), what you do, who your customers are, contacts, working hours with holiday exceptions, currency and payment methods, prepayment and cancellation terms, delivery, your own FAQ answers word for word, and what the agent may promise on its own versus leave to you. Each block says what the agent does with it, because these are not fields for their own sake: the agent speaks from them on every call. A completeness indicator makes the state visible — an empty profile means the agent cannot represent the business at all — and a "Fill in from a conversation" button hands the job to the agent, which asks one question at a time in chat.
- Price list — the only source of prices. Products and services, each with a price or a from–to range, a price note ("per hour", "from"), currency, unit, duration and an active switch. The agent quotes prices only from here: no matching item means "I'll check and call you back", never an improvised number.
- Customers. A searchable base sorted by the latest order; each card carries contacts, tags, a note, how many orders and how much was actually paid, and the full order and call history. The value is not the list but the warm-up of an inbound call: before the agent's first word, the caller's number is matched to a customer and their open orders, so a returning customer is greeted by name and asked about the job already running.
- Customer orders — the pipeline. Three working stages plus Cancelled, named in the words of your business type (New → In progress → Done by default; "Accepted → Picked up → Delivered" in transport; "Booked → Arrived → Done" in a salon), with payment as a separate axis — unpaid, partly paid or paid, with the amount received. That separation is deliberate: a finished but unpaid order must stay visible as debt instead of vanishing from the pipeline exactly when it matters most. An order holds the customer, line items with prices, the standard fields under the names your trade uses, the 0–3 custom fields your business type adds, an optional date and time, an address, a reminder, the assigned executor, and an append-only event feed carrying the name of whoever changed something. Dates are optional on purpose — "call back when it is ready" is a valid order — and orders without a date are counted separately, so a period filter can never hide them silently. The list filters by date with a mini calendar that marks days already carrying work.
- Order confirmation and payment. Orders the agent creates — from a call or from the chat — are marked "Unconfirmed" until the owner confirms them in the app; the owner always has the final word on what enters the pipeline. Payment is recorded by the owner on the order card: the status, the amount actually paid and the payment method (cash, card, transfer and so on). The owner can also dictate a payment to the agent, but only in their own private chat with it — on a call with a customer the agent never closes a debt on the caller's word.
- Business events in the Weyvox system chat. Order reminders, order proposals the agent gathered from calls, call summaries and firm commitments, team events, a reminder when an invoice reaches its due date while the order is still unpaid, and every Monday a digest of debtors — who owes how much, across completed but unpaid orders — all arrive in the Weyvox system chat on the Line tab, alongside the app's other service messages. That chat is written by the servers, not by you: it is a feed, not a conversation.
- The Monday report. Every Monday at 08:00 in the business's own time zone, the administrator gets one message in that same chat covering the week just gone: calls, how many the agent handled, how many were missed, SMS sent, orders created and for how much, and how much of that was paid versus still owed. It is the one place where "is this line actually working for me?" gets a number rather than a feeling. A week with nothing in it is not sent — an empty report every Monday teaches people to ignore the chat.
- Documents. The paperwork of the business: contracts, invoices, tax filings, registration papers, supplier and HR files, licences. Each document is read once on upload — the agent extracts its text and proposes the type, counterparty, number, date, amount and expiry for the owner to confirm — so afterwards any of them can be asked about in plain language, and the agent searches all of them at once. Expiry dates produce a push 30, 7 and 1 day ahead; licences and insurance quietly lapsing is exactly what this archive prevents. Documents count towards the account's storage quota (5 GB free, then 0.10 EUR per GB per month).
- How documents are protected — and what that does not mean. Documents, their text extracts, customer cards and order details are encrypted with AES-256-GCM under Weyvox's own key before they reach the database or file storage, so a raw copy of either is unreadable without that key — protection against leaks and against a storage provider, not against the agent. This is deliberately not end-to-end encryption: Weyvox holds the key, because the agent has to read a document in order to answer a question about it. The two requirements are mutually exclusive and reading was chosen; the app says so on the upload screen. For anything too sensitive even for that, a per-document switch ("do not let the agent read this") erases the text extract and the search index, so the file stays stored and visible to you while the agent cannot find or read it.
- Analytics. Two lenses over one period. The business: revenue received, amount billed, debt, order count, average cheque, new versus returning customers, top price-list items and where orders came from. The agent's own work: calls handled, how many became orders, the call-to-order conversion, minutes spoken, tasks finished and euros spent.
- How the agent works with all this. Reading is free — the profile, prices, customers, orders and documents are all available whenever relevant. Logging is autonomous: after a related call, a finished background task or news told in chat, it appends one short factual entry to the right order. It creates an order when a customer actually agrees to buy or book something, taking prices from the list. Two things it never does: quote a price that is not in the price list, and mark an order paid on a customer's word — payment is recorded by the owner on the order card, or dictated by the owner in their own private chat with the agent.
- Access control. The agent's access to Business management is a single switch in the agent's settings (on by default). Off, the agent can neither read nor write any of it — the pages themselves keep working for the owner.
Isolation
Isolation is enforced by design, not by policy: every agent request is bound to a single account, and the agent can only reach the data of the business it belongs to. There is no shared memory between businesses and no way for one business's agent to read another's anything.
The team — administrator and executors
A business with staff is two kinds of person, not two kinds of subscription. The administrator is the owner: the account, the line, the balance, the agent and every setting belong to them. An executor is someone who does the work — a driver, a fitter, a stylist — and who needs the job in front of them and nothing else.
The design decision that matters: an executor does not register. No phone number, no SMS code, no account of their own to forget. The administrator adds them in Business → Team with a first name, a last name, an optional phone number kept purely as a note, and three rights; saving shows an 8-character access code, which the administrator hands over by any channel they like. The executor taps "I have an executor code" under Sign in, types it, and is at work. The code is their login and their password until it is reset or they are removed.
- €10 per month per executor, taken from the administrator's balance at that executor's first sign-in and monthly afterwards. An executor never sees money in the app and never pays anything.
- A short balance does not sack anyone. If the charge cannot be taken, the executor keeps working for 7 days; after that they can still read their orders but cannot change them, until the charge goes through. The administrator can remove them from the team at any moment.
- Up to 10 executors per administrator.
- Three rights, effective immediately: sees prices (off: the amounts in their orders are hidden), marks payment (off: the payment status is hidden too), uses the agent (on by default; off: their Weyvox tab does not work).
- A new device asks for the code again, and the administrator is notified when it does. Resetting the code stops the old one working without deleting the person or their history.
- Removing someone and deleting their account are different things. When the administrator removes an executor from the team, the code stops working, their sessions end and their orders are released — but the sub-account itself remains. Only the person themselves deletes it, with Leave team in their own Settings. Deleting the administrator's account removes every executor with it.
What an executor actually sees — four tabs. Chats: the Weyvox system chat carrying their assignments and notices, plus personal chats by number. Weyvox: the agent, scoped to the orders assigned to them — no purchases, no balance, no agent settings. Orders: only the orders assigned to them, each with one button — the next stage, in the words of the business type ("Picked up", then "Delivered"). Settings: language, notifications, My spending, sign out, and Leave team, which deletes their sub-account. They do not see customers, documents, the price list, the line or analytics.
Assignment and accounting. The administrator puts an executor on an order; that executor gets a push and a message. A stage they change is visible to the administrator at once, and their name is written into the order's event feed. Anything they spend — agent turns, calls — comes off the administrator's balance and appears in Settings → Balance & usage with their name against it; the executor sees only their own line, under "My spending".
What the team is not. An executor does not place calls from the business line: tapping a customer's number opens the phone's own dialer, and the server refuses a call placed from a sub-account. There is no ring group — the line does not ring several phones at once. An executor does not get a phone number of their own. And there is no private administrator-to-executor chat beyond the system messages the app sends.
Your calendar
The agent can only avoid double-booking you if it knows when you are already taken. Until you connect a calendar it knows about one thing: the orders already written in Weyvox. A meeting standing in your own calendar does not exist for it, and it will cheerfully offer a caller exactly that hour. So Weyvox reads your calendar — and reads as little of it as possible.
Two sources, each with its own switch. Google Calendar is connected once through Google's own consent screen: you choose which of your calendars to use, and our server keeps it in step on its own, so it stays current even while your phone is off. The calendars already on your phone are the second route, and it needs no Google account at all: one permission covers everything the phone carries — iCloud, Google, Outlook, a work account — which matters because Apple offers no way to reach an iCloud calendar from a server. The trade-off is freshness: that half is refreshed by the app, so it is only as current as the last time the app ran.
What we take, and what we never take. From either source Weyvox stores the start and end times of your events, and nothing else. There is no field in our database for an event title, and there is not meant to be: knowing that you are busy from 14:00 to 15:00 is enough to protect the slot, and knowing that it is a doctor's appointment is not our business. Your own event names are shown to you on the calendar screen, read from the phone itself — they never reach us.
The screen. A month grid marks every day that already carries work, and under it the chosen day is listed entry by entry: orders taken by the agent or written by you, alongside the busy hours from the connected calendars. Tap an order to open it. Pull the list down to sync both sources at once. Everything on this screen is exactly what the agent sees when it works out your free windows — if it is not here, the agent does not know about it either.
Both directions. An order the agent accepts on a call is written back into your connected Google Calendar as an event, so a booking made by phone turns up where you already look. Cancel the order and the event goes with it. Weyvox skips its own events when it reads your calendar back, so an order can never block itself.
Connect or disconnect at any time in Settings → Calendar. Disconnecting revokes our access at Google straight away, and you can also remove it yourself from your Google account's list of connected apps. Deleting your Weyvox account does the same.
AI call notes
An AI note is a short factual summary (typically 2–4 sentences) produced after a call. The pipeline:
- Capture — the carrier produces the recording of the call. An audible notice is played to the other party.
- Transient processing — audio is transcribed per track and merged into a timeline; the audio file is deleted the moment transcription picks it up, and the transcript is deleted immediately after the note is written.
- One transcript per call. Everything spoken accumulates into a single transcript that belongs to that one call and to the one user the note is for. Nothing from any other call, and nothing belonging to any other person, is ever part of it.
- Generation — that single transcript is sent to the AI together with your own note instructions to write the note. The instructions come from your account and yours alone; each note is produced in its own isolated request built from exactly one call's transcript and one user's instructions.
- Delivery — the note lands in the related chat with the call record; users can steer what notes should focus on, or disable them entirely.
How your note instructions are scoped
Weyvox lets you tell the agent what your notes should focus on (and what to leave out). It is worth being precise about how far those instructions can reach, because it is a deliberate boundary of the design — not a promise we simply ask you to trust:
- Your instructions only ever shape your own calls' notes. Every note is generated on its own: one call's transcript plus the instructions stored on that account, in a request that contains nothing else. Your instructions are never combined with anyone else's transcript, and they never take part in generating another person's note.
- Rewriting them changes nothing outside your own notes. Because the boundary is structural — each note sees exactly one transcript and one account's instructions — there is no wording you could put in your instructions that would reach a different call or a different user's note. The isolation does not depend on what the instructions say.
- Where the processing happens. The recording is transcribed by our speech-to-text sub-processor, and the transcript plus your instructions are sent to our AI sub-processor to write the summary. Both act only to produce your note for your call, and both are bound by a data-processing agreement. The audio is deleted the moment transcription picks it up and the transcript the moment the note is written. If you switch AI notes off, none of this runs for that call.
Personal chats
Personal chats with customers and with people — by phone number, free. That is the whole of it: this is a convenience beside the line, not the reason Weyvox exists, and it gets one section rather than a product of its own.
They live on the Line tab beside the customer threads; you start one by number, and they carry text, photos, video, files, voice messages, locations and albums, with replies, forwarding, reactions, editing or deleting for everyone within 60 minutes of sending, and deleting for yourself at any time. A chat can be muted, blocked, or given a wallpaper chosen from your own photos — there is no wallpaper catalogue and nothing to buy. Media counts toward the 5 GB free storage allowance and is managed by category in Settings → Account → Data & storage. Messages are stored on Weyvox's servers in the EU and are not end-to-end encrypted; see Encryption and where each kind of data lives.
Push & incoming calls
- Messages and system events arrive as ordinary push notifications — a personal chat, a message in the Weyvox system chat, an order reminder — with per-chat mute windows and three preview levels (full text / sender only / silent). An executor is pushed when an order is assigned to them.
- Calls arriving on your phone line — that is, calls over the telephone network to your Weyvox number or forwarded from your business number; there is no other kind — are delivered by a dedicated call push that wakes the app so the phone rings with the native call screen, including from the lock screen. The audio path is prepared while it rings, so answering is instant, and it works on a cold start right after a reboot thanks to securely cached credentials. Because there are no app-to-app calls in Weyvox, this path carries nothing else.
The billing engine
Billing is Weyvox's most heavily engineered subsystem. Design principles: server-authoritative (the app can never invent a price), metered as it happens, safe against duplicates (retries can never double-charge), and transparent (every cent visible to the user).
- Two subscriptions, and only two. Neither the app nor the agent is sold by the month, but two things the user adds are: the Weyvox phone number (the fee depends on the country and the number, is shown before you buy, and the first month is included in the purchase), each executor on the team (€10 per month, from the administrator's balance — see Team). Alongside them, storage above the free 5 GB is metered at €0.10 per GB a month. Everything else is paid per use. The only one-time fee is €5 to connect your own business number.
- What a use actually costs. A call from the line is the per-minute rate for the destination country; a call the agent handles is that rate plus the agent's own work, about €0.30 a minute. An SMS to a customer is about €0.15 per segment. The agent chat is metered by the model's tokens; a web search is €0.05. Cloning your voice is free. Current figures live on the pricing page and in Settings → Account → Tariffs.
- Prepaid wallet. Top-ups are App Store / Google Play in-app purchases; each purchase is verified with the store and credited exactly once, and refunds handled by the store are reflected in your balance automatically.
- Welcome credit. Every new account is credited €5 on first registration — applied automatically and exactly once per user, with a welcome message in the system chat.
- Per-second call metering. A live agent call is charged minute-by-minute while it runs and settled to the exact second at hangup — as one entry per call that grows as the call goes on, so your history shows one clean line per call, not dozens of fragments.
- Exact telephony costs. Operator-call charges are driven by the carrier's own cost event emitted at hangup — the user pays a rate derived from the real cost of that exact call, applied seconds after it ends.
- Token metering, mirrored 1:1. AI usage is metered in the same five token categories the AI provider bills: base input, cache writes (5-minute and 1-hour tiers), cache reads, and output — per model family, so a task that mixes a fast model and a deep model prices each at its own rate. What the pricing page shows is exactly what you are charged.
- Safe to resume. If a background task restarts, it picks up its usage where it left off, so a resume can never refund or double-charge you.
- Subscription engine. Phone-number fees auto-charge monthly; if the balance is short the number keeps working for 30 days, then outgoing calls are blocked for 30 more, and it is released on day 60. Executors are charged on the same engine, with a 7-day grace period after which that executor can read but not change anything.
- Storage billing. A monthly job charges only full gigabytes above the free 5 GB.
- Every charge carries a name. In a business with executors, each operation in Balance & usage says who spent it — the administrator or the executor by name — so a month's spending can be read back to the person who caused it.
- Negative-balance settlement. Post-rated charges may take the balance below zero; the debt settles from the next top-up while free features — personal chats above all — keep working.
- Retention. Per-operation usage detail is kept 90 days, then whole days are physically deleted; payment records are kept for statutory accounting periods.
AI transparency & regulatory compliance
Weyvox's voice agent interacts directly with people on the phone, so it falls under the transparency rules of the EU AI Act (Regulation (EU) 2024/1689), Article 50, which apply from 2 August 2026. How Weyvox is built to meet them:
- AI disclosure — Art. 50(1) and 50(5). The agent always identifies itself as an AI assistant acting for its user at the start of every call — on outbound calls, on auto-answered incoming calls, and when it takes the seat in a live call. This is a built-in product rule the user cannot switch off, delivered clearly at the first moment of the interaction — exactly what Art. 50 requires: natural persons must be informed that they are interacting with an AI system, at the latest at the time of the first interaction.
- A synthesised (and optionally cloned) voice. The agent speaks in an AI-generated voice. A user may have it speak in a clone of their own voice; because the agent still gives the spoken AI disclosure at the start of the call, the other party is never misled into thinking a human is speaking. The clone is only ever the user's own voice — recorded by them, for their own agent — and is never used to impersonate a third party, so it is not a deceptive "deep fake" of the kind Art. 50(4) targets. The spoken disclosure is the human-facing transparency measure for the synthetic voice.
- Recording and consent. AI call notes need a recording; on operator calls Weyvox plays an audible notice to the other party, and the user is responsible for only recording where they are permitted to. See the Privacy Policy and Terms of Use.
- Voice data under the GDPR. A cloned voice is the user's personal data, processed only to produce their own agent's voice on the basis of their explicit consent, and deletable at any time — detailed in the Privacy Policy.
- Human accountability — GDPR Art. 22. The agent acts only on the user's instructions and within the capabilities they enable; Weyvox makes no automated decisions producing legal or similarly significant effects, and a human is always reachable at the support address.
Encryption, and where each kind of data lives
Weyvox states plainly what is protected and how, including where the protection stops. An app that overstates its encryption is worse than one that explains it, so this section says for each layer what it does and does not defend against. Weyvox does not offer end-to-end encryption: no part of the product is built so that only your device can read the data.
Transport, storage and access — the layer under everything
- In transit: everything between the app and Weyvox travels over TLS.
- At rest: the servers, the database and the file storage run in EU regions of our hosting providers, where data is encrypted on disk by the provider.
- Who can reach a row: access is bound to the account that owns it — and, for a business with a team, to that business — enforced at the API, at the database with row-level policies, and with least-privilege keys. Media is reachable only through short-lived signed links, never a public URL; identity documents live in private buckets.
- Time as a protection: the shortest possible life for the most sensitive data — call audio deleted the moment transcription picks it up, transcripts right after the note, KYC documents within 24 hours of activation. The full table is in the Privacy Policy.
- No ad or analytics SDKs in the app at all.
Application-level encryption under Weyvox's own key
On top of that, the sensitive business data in an account is encrypted with AES-256-GCM under a key held in Weyvox's server configuration, before it reaches the database or file storage — so a raw copy of either is unreadable without that key. It covers: business documents and their text extracts, customer cards and orders, the agent's memory, the server copy of your chats with the agent, and KYC files.
- It is not end-to-end encryption, and the reason is the product. Weyvox holds the key, and the agent reads this data in order to work for you — answer a customer, look up an order, cite a document. A design where only your phone could read it would be a design where the agent could not. Reading was chosen, deliberately.
- What it does protect against: a leaked database dump, a stolen storage bucket, a hosting provider's own access to the bytes.
- Your own override: the per-document switch "do not let the agent read this" erases that file's text extract and search index — the document stays stored and visible to you, and the agent cannot find or read it.
- Personal chats are not under this layer. They sit on the transport, at-rest and access protections above, and nothing more.
Personal chats — stated honestly
- Where they live: messages and media in personal chats are stored on Weyvox's servers in the EU, and they are not end-to-end encrypted. In plain terms this means they are readable by Weyvox's systems in the ordinary course of delivering the service — storing, delivering and syncing them — and that message content can be disclosed on a lawful request from a competent authority.
- People at Weyvox do not read your chats. They are opened only for such a lawful request, or for a support case you yourself opened.
- The agent sees a chat only when you open it there. The ✦ assistant inside a conversation is a toggle in the agent's settings, on by default and switchable off; while it is on, the messages your question concerns are passed to the agent for that answer. See Weyvox inside a personal chat.
- Calls and SMS are the telephone network, which by its nature cannot be private end to end: the carrier handles the numbers, the duration, the audio and the text of every message.
One phone at a time — and your history is there on the next one
A Weyvox account is active on one phone at a time: signing in on a new phone signs the old one out. Because the chats, the business records, the balance, the number and the agent's memory are held on the servers, they are all there again when you sign in on the new phone — nothing to transfer, nothing to scan, nothing lost with a lost handset. An executor signs in on a new device by entering their access code again, and the administrator is notified when they do.
On the phone itself, the app keeps a local database so it opens instantly and works offline; that database is encrypted with a key that exists only on that device and is marked never to be copied to another device through the platform's cloud keychain sync. Credentials live in the phone's secure storage and are cleared on sign-out. You can additionally set a PIN on the account and lock the app behind your phone's biometrics.
Conversations with the AI agent
- Shown from the phone, kept on the server. The agent chat history is displayed from a local database on the device; a server copy exists so the history is there again on a new phone. It is stored encrypted with Weyvox's own application-level key, never shown to anyone else, never used to train any model, and deleted with the account (the marker a deleted chat leaves behind is purged within 90 days).
- Transmitted only to be answered. To generate each reply, the message is sent to the AI provider whose model produces the answer, and is processed there as our processor under a data-processing agreement. Weyvox does not retain it there.
- What the agent does keep, server-side, on purpose: its long-term memory (facts the user asked it to remember, or that it learned while helping — all viewable and erasable in Settings), background tasks it is running, and transcripts of calls it made or answered, held for 24 hours so the user can ask follow-up questions about a call.
No system is perfectly secure. If a breach occurs, Weyvox notifies the CNIL and, where required, the people affected, in line with Arts. 33–34 GDPR.
Protecting the account: PIN and app lock
Weyvox offers two protections that are commonly mistaken for one another. They defend against different threats, and relying on the second alone leaves the first gap wide open. Both live on one screen — Settings → Account → Security — precisely so the difference is visible at a glance.
The PIN protects the account
Signing in to Weyvox normally means a phone number and the confirmation code sent by SMS. That is convenient, but it leaves the SMS as the only thing standing between an account and whoever manages to read it — through a swapped SIM, an intercepted message, or a glance at a lock screen. A PIN closes that gap. Once set, signing in from a different phone asks for a six-digit code that the user chose and that is never transmitted anywhere, so a confirmation code on its own no longer opens the account. It is optional and off by default; enabling it takes a minute and is the single most effective step a user can take for account safety.
- Any six digits — which combination to choose is the user’s decision. The app does not second-guess it.
- Recovery codes — setting a PIN issues ten one-time codes, displayed once and copyable in a single tap. They should be kept away from the phone, on paper or in a password manager: each one can stand in for the PIN exactly once.
- The set is stable — changing the PIN does not replace the codes: they are bound to the account, not to the current PIN, so a list written down months ago keeps working. Exactly two actions replace or remove it, and both warn first: reissuing the codes on purpose, and deleting the PIN (which deletes the codes with it, since without a PIN there is nothing for them to stand in for).
- Guessing is not a route — repeated wrong PIN attempts suspend entry for a period that grows with each series. Recovery codes carry their own allowance of ten attempts — as many as there are codes, so trying them one after another is normal use rather than something to be punished — and once it is spent, signing in from a new device is blocked for seven days.
- Forgotten PIN, no codes left — the account is still recoverable. A reset request is accepted and the account opens seven days later. The delay is deliberate: it gives the rightful owner time to see the request on their own phone and cancel it by entering their PIN, while making the same route useless to anyone in a hurry.
- Nobody will ever ask for it — not by email, not in the app, not through the AI assistant, not in support correspondence. There is no circumstance in which anyone but the account owner needs a PIN or a recovery code.
The app lock protects the phone
With the lock enabled, opening Weyvox on that handset requires the phone's own biometrics, with the device passcode as the fallback. It guards against a realistic and common risk: an unlocked phone left on a desk, borrowed, or taken.
The switch is labelled with whatever the handset actually supports, because Face ID is not universal: iPhone SE (2nd and 3rd generation) and iPhone 8 use Touch ID, and Android devices mostly use a fingerprint reader. The app reads the device's capability and names it accordingly rather than assuming.
It is worth being precise about the lock's limits, because assuming it also protects the account is a costly mistake. Biometrics are matched against the template enrolled in that specific handset — a template that never leaves the device and is never handed to any app. On a stranger's phone the check would therefore simply pass for them. Guarding the account against a sign-in from another phone is the PIN's job, not the lock's.
The setting belongs to that one phone and is stored only there. It requires biometrics to be configured in the phone's own settings first; until then the switch stays unavailable. The two features are complementary, and most users will want both: the lock for the phone in their pocket, the PIN for the account behind it.
Security & data engineering
- Application-level encryption is the primary model — the sensitive business data of an account (business documents and their text extracts, customer records and orders, the agent’s memory, the server copy of agent chats, KYC files) is encrypted with AES-256-GCM under Weyvox’s own key before it reaches the database or file storage; a raw copy of either is unreadable without it. It is not an exception carved out of something stronger: Weyvox holds the key, the agent reads this data to work, and the site says so wherever it comes up. See Encryption and where each kind of data lives.
- Per-account isolation by design — access to every record is bound to its owner and, for a business with a team, to that business; the agent is bound to one account per request, and each account has its own telephony identity. No cross-account data path exists. An executor's reach is narrowed further, to the orders assigned to them.
- Verified channels — every incoming call event is signature-verified before it is acted on, and internal callbacks from the agent's own infrastructure are accepted only from its known addresses.
- Secrets on device — credentials live in the phone’s secure storage and are cleared on sign-out. Server-side secrets live in a managed secret store, not in files on a machine. Found something? security.txt.
- Short-lived sensitive data — call audio for notes is deleted right after transcription; transcripts right after the note; KYC documents within 24 hours of activation; fired agent reminders after 30 days; cached contact names after 12 months without a call; the full retention table is in the Privacy Policy.
- No ads, no trackers — the app contains no third-party advertising or analytics SDKs. What we do measure is our own and aggregate: how much the service earned and cost, and how many accounts are active. It is counted from billing records and never touches the content of your calls, chats or documents, and it is never shared with anyone.
Using the app (quick reference)
- Sign-up: phone number + one-time SMS code (no email), first and last name, and one card confirming you are 18 or over and accept the Terms. Then the four-step first run. Staff do not sign up at all — they use "I have an executor code".
- Line: the first tab — your number, the auto-answer switch, the Weyvox system chat, a thread per customer number, and personal chats.
- Personal chats: by phone number, free; Saved messages is a personal notepad chat; blocking, notification and wallpaper (your own photos) controls per chat.
- Agent: talk to it in the Weyvox tab; ask it to call ("call and find out…"), to text a customer, give it background tasks, review its memory, choose its voice and — for chat — its model. Calls always run on Claude Haiku 4.5.
- Business: business information (including the business type), customers, orders, documents, analytics, team and PDF templates.
- Numbers: buy in Settings → Line → Phone number; some require KYC documents shown during purchase; the monthly fee depends on the country and is shown before you pay; the subscription starts on activation day. Your own business number connects for a one-time €5.
- Balance: top up via the App Store / Google Play; every charge is itemised in Settings → Balance & usage, with the name of whoever spent it; prices in Settings → Account → Tariffs and on the pricing page.
- Data: manage storage by category in Settings → Account → Data & storage; delete the account (irreversibly) in Settings → Account → Delete account — which also releases your numbers and removes your executors.
More question-style answers: the FAQ. Availability: iPhone (iOS), out now on the App Store; the Android app is in development, planned for 1 October 2026; no web client. Support: support@weyvox.com.